---
id: CVE-2026-20173
title: "A vulnerability in Cisco NX-OS Software could allow an unauthenticated, remote attacker to exhaust system resources, causing a denial of service (DoS) condition.\r\n\r\nThis vulnerability exists because rate limiting was improperly applied t…"
summary: "A vulnerability in Cisco NX-OS Software could allow an unauthenticated, remote attacker to exhaust system resources, causing a denial of service (DoS) condition.\r\n\r\nThis vulnerability exists because rate limiting was improperly applied t…"
severity: medium
cvss: 5.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L'
cwe:
  - CWE-770
vendor: Cisco
product: Cisco NX-OS Software
affected:
  - nx-os_software 8.2(5)
  - nx-os_software 7.3(5)D1(1)
  - nx-os_software 8.4(2)
  - nx-os_software 8.4(3)
  - nx-os_software 9.2(3)
  - nx-os_software 9.2(2v)
  - nx-os_software 7.3(4)D1(1)
  - nx-os_software 8.2(1)
  - nx-os_software 9.2(1)
  - nx-os_software 9.2(2t)
  - nx-os_software 9.2(3y)
  - nx-os_software 9.3(2)
  - nx-os_software 8.1(1)
  - nx-os_software 8.2(2)
  - nx-os_software 8.3(2)
  - nx-os_software 7.3(2)D1(3a)
  - nx-os_software 9.2(4)
  - nx-os_software 8.1(2)
  - nx-os_software 7.3(3)D1(1)
  - nx-os_software 8.2(3)
  - nx-os_software 8.4(1)
  - nx-os_software 7.3(0)DX(1)
  - nx-os_software 7.3(2)D1(1)
  - nx-os_software 9.3(1)
  - nx-os_software 7.3(2)D1(2)
  - nx-os_software 8.2(4)
  - nx-os_software 9.3(1z)
  - nx-os_software 9.2(2)
  - nx-os_software 8.1(2a)
  - nx-os_software 7.3(2)D1(3)
  - nx-os_software 8.3(1)
  - nx-os_software 7.3(1)D1(1)
  - nx-os_software 7.3(0)D1(1)
  - nx-os_software 9.3(3)
  - nx-os_software 7.3(2)D1(1d)
  - nx-os_software 9.3(4)
  - nx-os_software 7.3(6)D1(1)
  - nx-os_software 8.2(6)
  - nx-os_software 9.3(5)
  - nx-os_software 9.3(6)
  - nx-os_software 8.4(4)
  - nx-os_software 7.3(7)D1(1)
  - nx-os_software 9.3(5w)
  - nx-os_software 8.2(7)
  - nx-os_software 9.3(7)
  - nx-os_software 9.3(7k)
  - nx-os_software 7.3(8)D1(1)
  - nx-os_software 9.3(7a)
  - nx-os_software 8.2(7a)
  - nx-os_software 9.3(8)
published: '2026-10-07'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T18:17:19.937'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-20173'
references:
  - url: >-
      https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nxos-nscpdos-SnderkC7
    label: psirt@cisco.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-10-07T17:42:18.044011Z'
ingestedAt: '2026-10-07T16:38:22.255Z'
---

## Overview

A vulnerability in Cisco NX-OS Software could allow an unauthenticated, remote attacker to exhaust system resources, causing a denial of service (DoS) condition.

This vulnerability exists because rate limiting was improperly applied to some protocols. An attacker could exploit this vulnerability by sending a high rate of UDP or TCP connections to a data plane interface on an affected device. A successful exploit could allow the attacker to cause instability to various routing and control plane protocols through some packet loss and temporary disruptions, causing a DoS condition. This DoS condition will clear without manual intervention soon after the high rate of traffic is stopped.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
